← back
CVE-2025-59230

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 2.6%● KEVCWE-284
In short

The Windows Remote Access Connection Manager doesn't properly check who should have access to certain features, letting someone with basic user rights gain higher-level control on their own computer.

Technical detail

CWE-284 (Improper Access Control) in Windows Remote Access Connection Manager allows a local authenticated user to escalate privileges through inadequate access control mechanisms. The vulnerability requires local access and valid credentials, but enables privilege elevation to higher system levels with a CVSS score of 7.8.

Summary generated and translated by AI from the official description.
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →